Coordinating Adobe Experience Manager security patch deployment
This article provides guidance for Adobe Experience Manager administrators on how to plan and coordinate the deployment of a security patch to address a newly identified vulnerability.
Description description
A new security vulnerability has been identified in Adobe Experience Manager (AEM), and a corresponding security patch has been released. Administrators are responsible for organizing and scheduling the patch deployment across non-production and production environments. The patching process requires operating system reboots, resulting in brief downtime for the author and publish tiers. To minimize end-user impact, it is recommended to schedule patching and reboots outside of standard business hours and to update environments in a rolling fashion. No specific error messages or stack traces are associated with this proactive security update.
Environment
Adobe Experience Manager (all versions)
Symptoms
No immediate symptoms; this is a proactive security update to address vulnerabilities.
Cause
A security vulnerability identified in AEM requires a patch to maintain system security and compliance.
Resolution resolution
Follow the steps below to resolve the issue.
- Review the details of the relevant Adobe Experience Manager security bulletin to understand the vulnerabilities addressed and the recommended patching procedures.
- Plan the patch deployment for both non-production and production environments according to your organization’s change management processes.
- Notify all relevant stakeholders about the planned downtime due to required operating system reboots during the patching process.
- Schedule patching and reboots outside of standard business hours when possible to minimize end-user impact.
- Update author and publish tiers in a rolling fashion to further reduce downtime for end users.
- If using automation for patch deployment, note that the exact timing of reboots may vary, but efforts should be made to perform them during low-traffic periods.
- If manual patching is preferred, coordinate with your internal teams to schedule the update during an approved maintenance window.
- After patching, monitor all environments to ensure that services are running as expected and verify that the patch has been successfully applied.